Back to Insights
Email Security

Email Security: What DMARC Enforcement Actually Means

Email security for Saudi organisations: what DMARC enforcement mode actually does, why SPF and DKIM alone aren't enough, and the control NCA ECC names explicitly.

By Al Rashdan
3 min read
#email security services saudi arabia#email security solutions ksa#DMARC saudi arabia#anti phishing saudi arabia#business email compromise saudi arabia

A domain can have SPF, DKIM, and DMARC records published and still be freely spoofable, because DMARC has a monitoring mode that reports on failures without blocking a single message. Enforcement mode is the setting that turns those records from a reporting mechanism into an actual block, and it is the step a large share of domains never take.

01

What each record actually does

SPF (Sender Policy Framework) lists which mail servers are authorised to send on behalf of a domain. A receiving server checks the sending server's IP against this list.

DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outgoing mail, letting a receiving server verify the message wasn't altered in transit and genuinely came from a server holding the domain's private key.

DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving servers what to do when a message fails both SPF and DKIM alignment, and it has three possible policies: "none" (report only, deliver anyway), "quarantine" (deliver to spam), and "reject" (block delivery entirely).

02

Why "none" is the default almost everyone starts with, and stays on

Moving straight to "reject" risks blocking legitimate mail from a service nobody remembered configures as a sender on the domain, a marketing platform, a support ticketing tool, an internal application that sends notification email. The safe rollout path is genuinely staged: publish DMARC in "none" mode first, review the aggregate reports it generates to find every legitimate sender, fix any that fail authentication, and only then move to "quarantine" and eventually "reject".

The problem is that the staged rollout is exactly the part that gets abandoned. A domain lands on "none", the immediate compliance box is checked, and the move to enforcement, the step that requires reading reports and iterating, never happens. A DMARC record sitting in "none" mode indefinitely provides visibility into spoofing attempts and stops none of them.

03

Why this matters more than anti-malware filtering alone

Business email compromise, an attacker impersonating an executive or a supplier to request a wire transfer or a change of banking details, typically contains no malicious attachment and no malicious link. It is a well-written email from a spoofed or lookalike domain. Anti-malware filtering has nothing to detect in a message like that. Authentication enforcement and impersonation detection, catching the spoofed domain or the display-name mismatch, are the controls that actually address this attack pattern, and they are frequently the ones organisations skip in favour of filtering that catches a different threat entirely.

04

The control NCA ECC names explicitly

NCA ECC-2:2024's Cybersecurity Defence domain names email protection as a control requiring deployment and central management, not a mail platform's out-of-the-box spam filter left on default. A DMARC record stuck in monitoring mode, with no one reviewing the reports it generates, does not meet that bar even though the record technically exists.

A free cybersecurity maturity assessment scores email, endpoint, and identity controls against the NIST Cybersecurity Framework in about 15 minutes, and will flag whether email authentication is one of the gaps worth closing first.

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

Managed Security

Managed Security Pricing: MDR, SOC, and MSSP Models

What managed security really costs in the Kingdom: broken down by model, scope, and SLA so you can budget without surprises.

Read more
AI Governance

AI Governance ROI: Business Case for Executives

AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.

Read more
Compliance

NIST CSF 2.0 Mapped to NCA Requirements

Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%